Chinese‑Speaking APT Exploits ownCloud CVE‑2023‑49105 to Steal Nuclear Research Data in the Philippines
What Happened — A suspected Chinese‑language threat actor leveraged a known authentication‑bypass flaw (CVE‑2023‑49105) in an internet‑facing ownCloud instance and a separate WordPress vulnerability to infiltrate a Philippine nuclear research agency and a marine‑engineering firm supporting the Philippine Navy. Over 9 GB of sensitive files were exfiltrated and later discovered on an exposed server in Amsterdam.
Why It Matters for Compliance & Audit Readiness
- Demonstrates how unpatched public‑facing services can breach the Security principle of SOC 2, highlighting the need for continuous vulnerability management and evidence of timely patching.
- Shows the audit value of mapping misconfigurations (e.g., empty signing secrets) to SOC 2 control requirements and retaining immutable logs as proof of remediation.
Who Is Affected – Government nuclear research body; defense‑related marine engineering contractor (Philippines).
Recommended Actions –
- Immediately apply the ownCloud patch for CVE‑2023‑49105 and any pending WordPress updates.
- Conduct a full configuration review of all external services; enforce signed URL secrets and restrict WebDAV access.
- Integrate vulnerability scanning into a continuous‑monitoring pipeline and map findings to SOC 2 CC6.1 (Change Management) and CC7.1 (System Operations).
- Preserve forensic logs and evidence of remediation for audit review.
Source: Security Affairs
Technical Notes – Attack vector: exploitation of CVE‑2023‑49105 (ownCloud auth‑bypass) and an unnamed WordPress flaw; data types: nuclear research files, project‑management records; tools left on the attacker’s server included Sliver, Metasploit, and Mettle. Source: same as above